Vulnerability index

Browse CVEs

2,257 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2025-36144 IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. Watsonx.data Mitigation only Fix from $1,6002025-09-27 HIGH 8.8 CVE-2025-36202 IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to t… Webmethods Integration Mitigation only Fix from $1,9502025-09-22 MEDIUM 5.4 CVE-2025-36037 IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send una… Webmethods Integration Mitigation only Fix from $1,6002025-09-22 HIGH 7.2 CVE-2025-36143 IBM Lakehouse (watsonx.data 2.2) could allow an authenticated privileged user to execute arbitrary commands on the system due to improper validation … Watsonx.data Mitigation only Fix from $1,9502025-09-18 MEDIUM 5.5 CVE-2025-36244 IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the sy… Vios Mitigation only Fix from $1,6002025-09-16 MEDIUM 5.1 CVE-2025-36035 IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to… Powervm Hypervisor Mitigation only Fix from $1,6002025-09-14 MEDIUM 5.4 CVE-2025-36125 IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authen… Hardware Management Console Mitigation only Fix from $1,6002025-09-09 MEDIUM 5.3 CVE-2025-36003 IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error me… Security Verify Governance Mitigation only Fix from $1,6002025-08-28 CRITICAL 9.3 CVE-2025-2697 IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuadi… Cognos Command Center Mitigation only Fix from $2,3002025-08-26 HIGH 7.8 CVE-2025-1994 IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of th… Cognos Command Center Mitigation only Fix from $1,9502025-08-26 MEDIUM 6.1 CVE-2025-1494 IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi… Cognos Command Center Mitigation only Fix from $1,6002025-08-26 HIGH 7.8 CVE-2025-33120 IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigured cronjob due to execution wi… Qradar Incident Forensics Mitigation only Fix from $1,9502025-08-22 MEDIUM 5.4 CVE-2025-36042 IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary… Qradar Incident Forensics Mitigation only Fix from $1,6002025-08-22 MEDIUM 5.4 CVE-2025-1142 IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized r… Edge Application Manager Mitigation only Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-33008 IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authent… Sterling B2b Integrator Mitigation only Fix from $1,6002025-08-19 MEDIUM 5.4 CVE-2025-36088 IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an auth… Storage Ts4500 Library Firmware Mitigation only Fix from $1,6002025-08-15 HIGH 8.8 CVE-2025-36119 IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due … I Mitigation only Fix from $1,9502025-08-08 MEDIUM 6.5 CVE-2025-36023 IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive… Cloud Pak For Business Automation Mitigation only Fix from $1,6002025-08-08 HIGH 7.5 CVE-2025-36020 IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive credential info… Guardium Data Protection Mitigation only Fix from $1,9502025-08-06 CRITICAL 9.8 CVE-2025-3320 IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re… Tivoli Monitoring Mitigation only Fix from $2,3002025-08-06 CRITICAL 9.8 CVE-2025-3354 IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A re… Tivoli Monitoring Mitigation only Fix from $2,3002025-08-06 MEDIUM 6.1 CVE-2024-52890 IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs. Engineering Lifecycle Optimization Mitigation only Fix from $1,6002025-08-05 HIGH 7.4 CVE-2025-2824 IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an… Operational Decision Manager Mitigation only Fix from $1,9502025-08-01 MEDIUM 5.4 CVE-2025-33118 IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed… Qradar Security Information And Event Manager Mitigation only Fix from $1,6002025-08-01 HIGH 7.8 CVE-2025-33092 IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local u… Db2 Mitigation only Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-33114 IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under certain non-default conditio… Db2 Mitigation only Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-36010 IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to executable segments that are w… Db2 Mitigation only Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-2533 IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a specially c… Db2 Mitigation only Fix from $1,9502025-07-29 HIGH 7.5 CVE-2024-49342 IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cred… Informix Dynamic Server Mitigation only Fix from $1,9502025-07-28 MEDIUM 5.4 CVE-2024-49343 IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, w… Informix Dynamic Server Mitigation only Fix from $1,6002025-07-28